McDewey

Multi-vendor documentation library · semantic search · MCP endpoint at /mcp

Page 15

↗ View in doc context
page
15
source
cucm/v15/lsc-phone-install/lsc-phone-install.md
chunk_id
cucm::v15::lsc-phone-install::lsc-phone-install::14

there is no CAPF entry in the ITL file. Verify that the CAPF service was activated, and then restart the TFTP Service. Verify that the ITL file contains a CAPF certificate after the restart, reset the phone to pick up the latest ITL file, and then retry your certificate operation. If the CAPF server entry in the phone's security settings menu displays as hostname or fully qualified domain name, confirm the phone is able to resolve the entry to an IP address. LSC: Connection Failed The LSC fails to install. The phone’s Status Messages show "LSC: Connection Failed". This can indicate one of these conditions: A mismatch between the CAPF certificate in ITL file and the current certificate, the CAPF service is in use. • The CAPF service is stopped or deactivated. • The phone cannot reach the CAPF service over the network. • Verify the CAPF service is activated, restart the CAPF service, restart TFTP services where started, reset the phone to pick up the latest ITL file, and then retry your certificate operation. If the problem persists, take a packet capture from the phone and the CUCM Publisher, and analyze in order to see if there is bidirectional communication on port 3804, the default CAPF service port. If not, there can be a network issue. LSC: Failed The LSC fails to install. The phone’s Status Messages show "LSC: Failed". The Phone Configuration web page shows "Certificate Operation Status: Upgrade Failed: User Initiated Request Late/Timedout". This indicates that the Operation Completes By time and date have expired or are in the past. Enter a date and time that is at least one hour into the future, and then retry your certificate operation. LSC: Operation Pending The LSC fails to install. The phone's Status Messages show "LSC: Connection Failed". The phone Configuration page shows "Certificate Operation Status: Operation Pending". There are different reasons that one can see the Certificate Operation Status: Operation Pending status. Some of them include: ITL on the phone is different than the one currently used on the configured TFTP servers. • Issues with corrupt ITL's. When this happens, devices lose their trusted status and the command utils itl reset localkey needs to be run from the CUCM Publisher to force the phones to now use the ITLRecovery certificate. If the cluster is in mixed-mode, you need to use the command utils ctl reset localkey. Next, you see an example of what you can see when you attempt to view a corrupt ITL from the CLI of CUCM. If there is an error when you try to view the ITL and attempt to run the utils itl reset localkey command, but you see the second error, this can be a defect Cisco bug ID CSCus33755. Confirm if the version of the CUCM is affected. •